Google Releases Security Update for Chrome

Original release date: September 25, 2015

Google has released Chrome version 45.0.2454.101 to address multiple vulnerabilities for Windows, Mac, and Linux. Exploitation of one of these vulnerabilities may allow a remote attacker to obtain sensitive information from an affected system.

Users and administrators are encouraged to review the Chrome Releases page and apply the necessary update.


This product is provided subject to this Notification and this Privacy & Use policy.

USN-2746-2: Simple Streams regression

Ubuntu Security Notice USN-2746-2

25th September, 2015

simplestreams regression

A security issue affects these releases of Ubuntu and its
derivatives:

  • Ubuntu 15.04
  • Ubuntu 14.04 LTS

Summary

USN-2746-1 introduced a regression in Simple Streams.

Software description

  • simplestreams
    – Library and tools for using Simple Streams data

Details

USN-2746-1 fixed a vulnerability in Simple Streams. The update caused a
regression preventing MAAS from downloading PXE images. This update fixes
the problem.

We apologize for the inconvenience.

Original advisory details:

It was discovered that Simple Streams did not properly perform gpg
verification in some situations. A remote attacker could use this to
perform a man-in-the-middle attack and inject malicious content into
the stream.

Update instructions

The problem can be corrected by updating your system to the following
package version:

Ubuntu 15.04:
python-simplestreams

0.1.0~bzr354-0ubuntu1.15.04.2
simplestreams

0.1.0~bzr354-0ubuntu1.15.04.2
python-simplestreams-openstack

0.1.0~bzr354-0ubuntu1.15.04.2
python3-simplestreams

0.1.0~bzr354-0ubuntu1.15.04.2
Ubuntu 14.04 LTS:
python-simplestreams

0.1.0~bzr341-0ubuntu2.3
simplestreams

0.1.0~bzr341-0ubuntu2.3
python-simplestreams-openstack

0.1.0~bzr341-0ubuntu2.3
python3-simplestreams

0.1.0~bzr341-0ubuntu2.3

To update your system, please follow these instructions:
https://wiki.ubuntu.com/Security/Upgrades.

After a standard system update you need to restart any services that
make use of python-simplestreams or python3-simplestreams to make
all the necessary changes.

References

LP: 1499749

CVE-2015-7323 – Secure Meeting (Pulse Collaboration) issue may allow authenticated users to bypass meeting authorization

Posted by Profundis Labs on Sep 25

Profundis Labs Security Advisory
https://profundis-labs.com/advisories/CVE-2015-7323.txt

Product:
================================
Junos Pulse Secure Meeting

Secure Meeting is a part of the Junos Puls Collaboration software, which
allows you to organize and holding virtual meetings with internal and
external users via the Juniper Access Gateway.

Vulnerability Type:
===================
Insufficient Authorization Checks

CVE Reference:…

CVE-2015-7323 – Secure Meeting (Pulse Collaboration) issue may allow authenticated users to bypass meeting authorization

Posted by Profundis Labs on Sep 25

Profundis Labs Security Advisory
https://profundis-labs.com/advisories/CVE-2015-7323.txt

Product:
================================
Junos Pulse Secure Meeting

Secure Meeting is a part of the Junos Puls Collaboration software, which
allows you to organize and holding virtual meetings with internal and
external users via the Juniper Access Gateway.

Vulnerability Type:
===================
Insufficient Authorization Checks

CVE Reference:…

Re: An iOS oversight: exploiting device trust and backups

Posted by Luis ‘Pope’ Gómez on Sep 25

You make an interesting point here, David.

About this topic, I would recommend this brilliant paper by Mr. Zdziarski:
http://www.zdziarski.com/blog/wp-content/uploads/2014/08/Zdziarski-iOS-DI-2014.pdf

I proposed a software solution to apply various mitigations in jailbroken
devices; including: deleting the pairing records (so that your iOS device
will not continue trusting other comptuers) and disabling a number of
services (for instance: if I…